A founding initiative of ×
Participant Handbook

Privacy Policy

How AusISA collects, uses, stores, and protects your personal information, and the rights you have over it under the Privacy Act and the Australian Privacy Principles.

Document ID GOV-013 Version 1.1 Effective May 2026 Next review July 2027

1.About this Policy

1.1

Australian Information Security Academy Pty Ltd (AusISA, we, us) is committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1.2

This policy explains how we collect, hold, use, and disclose personal information in connection with our training courses and website.

2.Information We Collect

2.1

We collect personal information that you provide directly when registering for a course or signing up for notifications:

2.1.1

Identity: first name, last name;

2.1.2

Contact: email address, phone number;

2.1.3

Professional: organisation, role/title, IRAP assessor status and assessor number (if applicable);

2.1.4

Eligibility: Australian citizenship status, existing security clearance status, certification evidence and CV documents provided for eligibility verification;

2.1.5

Accessibility: dietary requirements and accessibility needs (for in-person courses);

2.1.6

Other: any additional notes you provide in registration or notification forms.

2.2

We do not collect financial information directly. Payment processing is handled by our third-party payment provider, Airwallex Pty Ltd, which operates under its own privacy policy.

2.3

Where a course or event is vetted, we collect the evidence described in the Participant Vetting Policy for the purpose of the vetting decision.

3.How We Use Your Information

3.1

We use the information we collect for the following purposes:

3.1.1

processing and managing your course registration and enrolment;

3.1.2

issuing invoices and confirming payment;

3.1.3

providing access to course materials via our learning management system;

3.1.4

arranging catering and accessibility accommodations for in-person courses;

3.1.5

verifying IRAP assessor status with the Australian Signals Directorate where applicable;

3.1.6

sending course-related communications (confirmations, reminders, pre-reading materials);

3.1.7

notifying you of new course dates if you have opted in;

3.1.8

responding to your enquiries.

4.Where Your Information Is Stored

4.1

Your personal information is stored in Australia using Amazon Web Services (AWS) infrastructure in the Asia Pacific (Sydney) region (ap-southeast-2). This includes registration and enrolment records in encrypted databases, course progress and assessment data in our learning management system, and email notification preferences.

4.2

All data is encrypted at rest and in transit.

4.3

We do not transfer personal information outside of Australia except as required for payment processing through Airwallex (which may process transactions through its global infrastructure) and for email delivery through AWS Simple Email Service.

5.Who Has Access

5.1

Access to your personal information is restricted to: AusISA administrative staff, for course administration, enrolment management, and support; course facilitators, limited to information necessary for delivering training (name, organisation, assessor status); and Airwallex Pty Ltd, for payment processing only, governed by their privacy policy.

5.2

We do not sell, rent, or share your personal information with third parties for marketing purposes.

5.3

We may disclose information where required or authorised by Australian law.

6.How Long We Retain Your Information

6.1

Course registrations and enrolment records: retained for 7 years from the date of course completion (P-013), consistent with Australian tax record-keeping requirements.

6.2

Learning management system accounts: retained for the duration of your enrolment plus 2 years (P-014) to support ongoing professional development records.

6.3

Notification subscriptions: retained until you unsubscribe, at which point your record is deleted.

6.4

Payment records: retained by Airwallex in accordance with their retention policy.

6.5

Retention and disposal are managed under the Record Management Policy.

7.Your Rights

7.1

Under the Australian Privacy Principles, you have the right to:

7.1.1

access the personal information we hold about you;

7.1.2

request correction of any inaccurate, incomplete, or out-of-date information;

7.1.3

unsubscribe from marketing communications at any time using the link in any notification email;

7.1.4

request deletion of your personal information (subject to our legal record-keeping obligations);

7.1.5

complain if you believe we have breached the APPs.

7.2

Access requests are handled under the Record Management Policy, which explains the response timeframe and the limited circumstances in which released records may be sanitised.

8.Security

8.1

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. Our security measures include:

8.1.1

encryption of data at rest and in transit (TLS 1.2+);

8.1.2

access controls and multi-factor authentication for administrative systems;

8.1.3

regular database backups with tamper-proof retention policies;

8.1.4

infrastructure hosted in Australian data centres (AWS Sydney).

9.Cookies and Analytics

9.1

Our website does not use tracking cookies or third-party analytics services.

9.2

We may use essential cookies for session management on our learning management system.

10.Changes to This Policy

10.1

We may update this policy from time to time. Material changes will be noted on this page with an updated revision date.

11.Contact Us

11.1

If you have questions about this privacy policy, wish to access or correct your information, or wish to make a complaint, contact us by email at privacy@ausinfosec.academy, or by post at Australian Information Security Academy Pty Ltd, Level 4, 1 Moore Street, Canberra ACT 2601.

11.2

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au/privacy/privacy-complaints.